Skip to content

Legal

Privacy Policy

Last updated: 22 September 2025

Your privacy matters to us. This policy explains what we collect, why, and your rights under the Protection of Personal Information Act (POPIA).

1. Introduction & Scope

Ndayeni Solutions Pty Ltd (“Ndayeni Solutions”, “we”, “us”) is a South African registered information technology services company based at 4099 Finger Fish Street, Kaalfontein, Midrand, 1635. We provide IT support, computer repairs, networking & Wi-Fi, CCTV & security, printer & office technology, web design, graphic design, digital automation and digital skills training to small businesses and homes across South Africa.

This Privacy Policy explains how we collect, use, disclose and protect your personal information when you interact with us through our website at ndayenisolutions.co.za, our contact form, WhatsApp, email or telephone, our digital training academy, and during the delivery of our services. It applies to website visitors, enquiry contacts, training applicants, students and clients.

We are committed to protecting your privacy and complying with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) (“POPIA”), the Promotion of Access to Information Act, 2000 (Act No. 2 of 2000) and other applicable South African data protection laws. This policy is reviewed regularly and updated as our services evolve.

2. Information We Collect

We only collect personal information that is necessary for the purposes set out in this policy. We group what we collect into the following categories:

Personal information you provide directly

Full name, email address, phone number, South African ID or passport number, residential or business address, and related details you give us when you submit a contact form, apply for training, request a quote, become a client or enrol in a course.

Business information

Company name, your position or role, business address and related details you provide when you contact us on behalf of an organisation.

Technical information collected automatically

IP address, browser type and version, operating system, device information, referring pages and basic usage data collected automatically when you visit our website or use our online services.

Communication records

Records of emails, WhatsApp messages, telephone calls and meeting notes you exchange with us. We keep these to deliver and improve our service, to verify your identity and to keep an accurate history of your enquiry or project.

Special categories of personal information

We do not collect special personal information (such as health, religion, race, political opinions or biometric data) except where it is strictly necessary for a specific service you have requested. For example, CCTV installation may incidentally capture images of your property. In every such case, we will explain why and obtain your explicit consent before collecting or processing this information.

3. How We Use Your Information

We process your personal information for the following specific, limited purposes:

  • Providing the IT services, support and maintenance you have requested from us.
  • Responding to your enquiries, requests for quotes and follow-up communications.
  • Processing training academy applications, enrolment and student administration.
  • Issuing certificates of completion and verifying qualifications when you or a third party you authorised requests verification.
  • Sending service-related communications such as appointment reminders, status updates and security notices.
  • Billing, invoicing and account administration.
  • Improving our services, website and customer experience.
  • Complying with our legal obligations and keeping records we are required to maintain under South African law.

We do not use your personal information for any purpose that is incompatible with the purposes for which it was originally collected. Where we wish to use it for a new purpose, we will tell you first and, where required, seek your consent.

5. Information Sharing & Third Parties

We do not sell your personal information. We only share it in the following circumstances:

  • When you have given us your consent to do so.
  • When we are required to by law, regulation or a court order.
  • With service providers and processors who act on our behalf under written contract and who are themselves required to comply with POPIA, including cloud hosting, email delivery and payment processing providers.

Categories of third parties we work with:

ProviderRegionWhat they receiveWhy
Cloud hosting (Vercel)Global edge networkApplication code, basic deployment metadataHosts the marketing site & web applications
Database hosting (Supabase)Selected regional data centreStructured records you submit (training applications, contact form, academy data)Stores application & academy data in encrypted databases
Email / SMTP providersSouth Africa & EUEmail address, name, message content you send usDelivers our replies, notifications and certificates
Payment processorsSouth AfricaCard or EFT details (handled by the processor — not stored by us)Processes course fees and invoices (added as services grow)
Google (Analytics & Business Profile)United States with EU controlsAggregated, pseudonymised usage data — only with your consentHelps us understand site usage and improve discoverability

Each of these providers is contractually bound to process personal information only on our instructions and to safeguard it in line with POPIA. Where a provider is located outside South Africa, we rely on the safeguards described in Section 11 below.

6. Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including any legal, accounting or reporting requirements. After that, we securely delete it or anonymise it so that it can no longer identify you.

Specific retention periods

  • Enquiries & quotes12 months after last contact
  • Client service records5 years (SARS record-keeping)
  • Training academy records7 years (SAQA requirements)
  • CCTV footage30–90 days per client contract
  • Website & server logs30 days
  • Issued certificatesPermanent (verification purpose)

When retention is no longer required, personal information is securely deleted or rendered permanently anonymous using industry-standard methods. Backups containing deleted information are overwritten on the next scheduled backup rotation.

7. Security Measures

We take the security of your personal information seriously and apply a combination of technical, physical and organisational measures to protect it against unauthorised access, loss, destruction, alteration or disclosure.

Technical

  • TLS encryption for data in transit.
  • Encrypted databases at rest.
  • Secure password hashing using PBKDF2 with unique salts.
  • Strict access controls and least-privilege accounts.
  • Regular security review and dependency updates.

Physical

  • Secure storage of any physical client records.
  • Locked premises and access-controlled workspaces.
  • Secure disposal of printed personal information.

Organisational

  • Staff training on POPIA and data handling.
  • Written confidentiality agreements with all staff.
  • Least-privilege access to systems and records.
  • Documented incident response procedure.

Incident response: In the event of a confirmed data breach that poses a real risk to your rights, we will take reasonable steps to contain the breach, notify affected data subjects and notify the Information Regulator as required by POPIA (Section 22), as soon as reasonably possible after the breach has been confirmed.

8. Your Rights Under POPIA

POPIA gives you specific rights over your personal information. The cards below summarise each right; you can exercise any of them at any time.

Right to Access
Request a copy of the personal information we hold about you, in an accessible format.
Right to Correct
Ask us to update or correct any personal information that is inaccurate, out of date or incomplete.
Right to Delete
Request deletion of your personal information where retention is not required by law or for legitimate purposes.
Right to Object
Object to processing carried out for direct marketing or under our legitimate interests, subject to conditions.
Right to Withdraw Consent
Withdraw your consent at any time. Processing that relied solely on that consent will then stop.
Right to Complain
Lodge a complaint with the Information Regulator if you are not satisfied with how we have handled your information.

How to exercise your rights

Email us at info@ndayenisolutions.co.za with the subject line “POPIA Request” and tell us which right you wish to exercise. We will verify your identity and respond within 30 days as required by POPIA (Sections 23 to 24). There is no charge for reasonable requests, although a reasonable fee may apply to manifestly unfounded or excessive requests.

9. Cookies & Tracking Technologies

We use a minimal set of cookies and similar technologies on our website:

  • Essential cookies: required for the site to function (for example, keeping you logged in to the academy admin area or protecting forms). These cannot be disabled if you wish to use those features.
  • Analytics cookies: used to understand how visitors use our site so we can improve it. These are only set after you have given your consent.
  • No advertising cookies: we do not use third-party advertising or tracking cookies.

You can manage or delete cookies through your browser settings at any time. Doing so may affect some features of the site. See your browser’s help pages for instructions, or visit allaboutcookies.org for general guidance.

10. Children’s Privacy

Our services are not directed at children under the age of 18, and we do not knowingly collect personal information from children. Training academy applicants must be 18 or older, or have written consent from a parent or legal guardian.

If you are a parent or guardian and you believe we have collected personal information from your child without consent, please contact us using the details in Section 13 and we will take reasonable steps to delete that information.

11. International Transfers

Some of our service providers process personal information outside South Africa. Under POPIA (Sections 73 to 76), we will only transfer your personal information to a foreign country if that country has an adequate level of data protection, or if the transfer is protected by appropriate safeguards such as standard contractual clauses or binding corporate rules, or one of the other lawful grounds applies.

Specific providers and their regions:

  • Vercel — global edge network. Serves the website from the location closest to you, under GDPR-aligned data processing terms.
  • Supabase — chosen regional data centre. Stores application and academy data with encryption at rest and in transit.
  • Google — United States with EU data-protection controls (Google Analytics and Google Business Profile, only used with your consent).

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, POPIA guidance or best practice. When we do, we will publish the updated version on this page with a new “Last updated” date at the top.

For material changes (such as new categories of information we collect or new third parties we share it with), we will also post a notice on our homepage for at least 30 days so you have an opportunity to review the changes before they take effect.

13. Contacting Us

If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact our Information Officer:

Nhlakanipho Ntshangase — Information Officer

Ndayeni Solutions Pty Ltd

info@ndayenisolutions.co.za

083 800 6989

4099 Finger Fish Street, Kaalfontein, Midrand, 1635, South Africa

14. Complaints

We aim to resolve any privacy concern quickly and fairly. Please contact us first using the details in Section 13 — we will investigate and respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator (South Africa):

Information Regulator (South Africa)

5th Floor, River Side Office Park, 130 Nana Sita Street, Sunnyside, Pretoria

complaints@inforegulator.org

inforegulator.org.za

Please attempt to resolve your concern with us first. This gives us the opportunity to investigate, explain or put things right before the matter is escalated.

Need to ask something?

If you have a question about how we handle your personal information, we’re happy to help.

Contact us

This policy is provided for general information. For specific legal advice on POPIA compliance, consult a qualified attorney.